Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1423824 > unrolled thread

[PATCH] gpiolib: avoid uninitialized data in gpio kfifo

Started byArnd Bergmann <arnd@arndb.de>
First post2016-06-16 11:10 +0200
Last post2016-06-16 12:10 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] gpiolib: avoid uninitialized data in gpio kfifo Arnd Bergmann <arnd@arndb.de> - 2016-06-16 11:10 +0200
    Re: [PATCH] gpiolib: avoid uninitialized data in gpio kfifo Linus Walleij <linus.walleij@linaro.org> - 2016-06-16 12:10 +0200

#1423824 — [PATCH] gpiolib: avoid uninitialized data in gpio kfifo

FromArnd Bergmann <arnd@arndb.de>
Date2016-06-16 11:10 +0200
Subject[PATCH] gpiolib: avoid uninitialized data in gpio kfifo
Message-ID<rKBtf-6qC-5@gated-at.bofh.it>
gcc reports a theoretical case for returning uninitialized data in
the kfifo when a GPIO interrupt happens and neither
GPIOEVENT_REQUEST_RISING_EDGE nor GPIOEVENT_REQUEST_FALLING_EDGE
are set:

drivers/gpio/gpiolib.c: In function 'lineevent_irq_thread':
drivers/gpio/gpiolib.c:683:87: error: 'ge.id' may be used uninitialized in this function [-Werror=maybe-uninitialized]

This case should not happen, but to be on the safe side, let's
return from the irq handler without adding data to the FIFO
to ensure we can never leak stack data to user space.

Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Fixes: 61f922db7221 ("gpio: userspace ABI for reading GPIO line events")
---
 drivers/gpio/gpiolib.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/gpio/gpiolib.c b/drivers/gpio/gpiolib.c
index 8b3db593f356..3466e6198351 100644
--- a/drivers/gpio/gpiolib.c
+++ b/drivers/gpio/gpiolib.c
@@ -674,6 +674,8 @@ irqreturn_t lineevent_irq_thread(int irq, void *p)
 	} else if (le->eflags & GPIOEVENT_REQUEST_FALLING_EDGE) {
 		/* Emit high-to-low event */
 		ge.id = GPIOEVENT_EVENT_FALLING_EDGE;
+	} else {
+		return IRQ_NONE;
 	}
 
 	ret = kfifo_put(&le->events, ge);
-- 
2.9.0

[toc] | [next] | [standalone]


#1423897

FromLinus Walleij <linus.walleij@linaro.org>
Date2016-06-16 12:10 +0200
Message-ID<rKCpk-72x-31@gated-at.bofh.it>
In reply to#1423824
On Thu, Jun 16, 2016 at 11:02 AM, Arnd Bergmann <arnd@arndb.de> wrote:

> gcc reports a theoretical case for returning uninitialized data in
> the kfifo when a GPIO interrupt happens and neither
> GPIOEVENT_REQUEST_RISING_EDGE nor GPIOEVENT_REQUEST_FALLING_EDGE
> are set:
>
> drivers/gpio/gpiolib.c: In function 'lineevent_irq_thread':
> drivers/gpio/gpiolib.c:683:87: error: 'ge.id' may be used uninitialized in this function [-Werror=maybe-uninitialized]
>
> This case should not happen, but to be on the safe side, let's
> return from the irq handler without adding data to the FIFO
> to ensure we can never leak stack data to user space.
>
> Signed-off-by: Arnd Bergmann <arnd@arndb.de>
> Fixes: 61f922db7221 ("gpio: userspace ABI for reading GPIO line events")

Patch applied, good catch, thanks!

Yours,
Linus Walleij

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web